Enabling LDAP Authentication in Mattermost: A Step‑by‑Step Guide
Configure LDAP authentication in Mattermost: install the plugin, map attributes, test the connection, and troubleshoot common failures. A concise guide for admins needing single sign‑on and group sync.
09 Feb 2026, 00:53 UTC

Goal
Integrate your Mattermost instance with an existing LDAP directory so that users can authenticate with their corporate credentials and optionally have group membership synced. The result is a single sign‑on experience and streamlined user management.
Prerequisites
- Mattermost Enterprise edition or a third‑party LDAP plugin installed.
- Administrative access to the Mattermost System Console.
- LDAP server details: host, port, bind DN, bind password, user search base, and group search base.
- Read permission for the bind DN on the user and group objects.
- Optional: TLS certificates if the LDAP server requires secure connections.
Step 1: Install the LDAP Plugin (if not using Enterprise)
- Download the plugin package from the Mattermost plugin repository or a vendor that supports LDAP.
- Place the
mattermost-ldap-plugin.zipfile in the/pluginsdirectory of your Mattermost installation. - Restart Mattermost to load the plugin.
- Verify the plugin appears under System Console > Plugins > Plugin Settings and is enabled.
Step 2: Configure LDAP Settings
Navigate to System Console > Authentication > LDAP. Fill in the following fields:
| Field | Description |
|---|---|
| Server Host | e.g., ldap.example.com or IP address. |
| Port | Default 389 for plain, 636 for LDAPS. |
| Use TLS | Check if the server requires TLS/LDAPS. |
| Bind DN | Distinguished name with read access, e.g., cn=admin,dc=example,dc=com. |
| Bind Password | Securely store the password; use a placeholder like {LDAP_BIND_PASSWORD} for secrets management. |
| User Search Base | Base DN where user objects reside, e.g., ou=Users,dc=example,dc=com. |
| User Search Filter | LDAP filter to find user objects, e.g., (objectClass=person). |
| UID Attribute | Attribute used as Mattermost username, e.g., uid or sAMAccountName for AD. |
| Group Search Base | Optional: base DN for group objects. |
| Group Search Filter | Optional: filter to find group objects, e.g., (objectClass=group). |
| Group Filter | Optional: restrict imported groups, e.g., (cn=team-*). |
| Group Mapping | Map LDAP group names to Mattermost team names. |
Example configuration snippet for mattermost.ini (if using the built‑in LDAP support):
[LDAP]
Host = ldap.example.com
Port = 389
UseTLS = false
BindDN = cn=admin,dc=example,dc=com
BindPassword = {LDAP_BIND_PASSWORD}
SearchBase = ou=Users,dc=example,dc=com
SearchFilter = (objectClass=person)
UIDAttribute = uid
EmailAttribute = mail
FirstNameAttribute = givenName
LastNameAttribute = sn
GroupSearchBase = ou=Groups,dc=example,dc=com
GroupSearchFilter = (objectClass=group)
GroupFilter = (cn=team-*)
SyncGroups = true
Step 3: Test and Validate
- Click Test Connection in the LDAP section. A green success message confirms network reachability and credential validity.
- Attempt to log in with a known LDAP user. Successful authentication should display the user’s full name and email as configured.
- Check the logs (
mattermost.log) for entries likeLDAP authentication succeeded for user <uid>to confirm backend usage.
Common Troubleshooting
- Connection refused or timeout: Verify host, port, and network firewall rules. Ensure TLS settings match the server’s configuration.
- Bind DN authentication failed: Confirm the DN and password are correct and that the account has read access to user objects.
- Missing or incorrect usernames/emails: Check that the
UIDAttribute,EmailAttribute,FirstNameAttribute, andLastNameAttributematch the LDAP schema. - Unexpected group imports: Review the
GroupFilterandGroupMappingsettings to restrict or map groups correctly.
Recovery Options
If users cannot log in after configuration:
- Re‑enable Test Connection and review the detailed error message.
- Check the
mattermost.logfor LDAP error codes (e.g.,LDAP: 49 - 0000052Bfor bad credentials). - Verify that the UID attribute used by Mattermost matches the LDAP attribute that contains the user’s login name.
- If group sync is causing issues, disable
SyncGroupstemporarily and re‑enable after confirming user authentication works. - Consult your LDAP administrator to ensure the bind account has the necessary permissions and that the user’s account is not disabled.
Conclusion
LDAP integration in Mattermost is a powerful way to centralize authentication and user provisioning. By carefully mapping attributes and validating each step, you can achieve a smooth single sign‑on experience for your organization.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.